Klense Privacy Policy

Effective date: July 11, 2026 Last updated: August 3, 2026

Klense is a personal hygiene system for iOS, operated by Cole Thapanawat, sole proprietor ("Klense," "we," "us"). This policy explains what information the Klense app collects, how it is used, who processes it, and the controls you have over it.

The short version:

1. Who this policy covers

This policy applies to the Klense iOS app and the account you create in it. It does not cover Apple's own processing of your App Store purchases (see Apple's privacy policy) or third-party websites we link to.

2. Information we collect

2.1 Account information

When you create an account or sign in we collect:

Klense does not offer password-based sign-up, so we never receive or store a password; sign-in is performed by Apple or Google and handled by our backend provider (Supabase). Your sign-in session is stored securely in the iOS Keychain on your device.

2.2 Hygiene personalization profile

During onboarding you answer questions that tailor your routine. We collect exactly these attributes:

These are preference and lifestyle attributes used solely to personalize your hygiene routine. Klense does not collect medical records, diagnoses, medications, age, gender, or any clinical health data, and the app is not a medical service.

2.3 Your routine and activity

2.4 Subscription information

Klense is free to use, with an optional Klense Premium subscription. If you never subscribe, no subscription record is created for your account.

If you do subscribe, Apple processes your payment — we never receive your payment card details — and we store your subscription status, plan (monthly/annual), start and expiry dates, and the Apple transaction identifier, plus a log of subscription lifecycle events (e.g. started, renewed, expired), so your subscription works across your devices.

Because the AI coach is a paid feature, each message you send to it is accompanied by the Apple-signed record of your subscription (a StoreKit transaction), which our backend checks against Apple's signature before generating a reply. That record is verified in memory for that one request: we do not store it, and it is never sent to Google (Section 4).

2.5 AI chat (stored on your device only)

Your conversations with the AI coach are stored only on your device. There is no chat-message table in our cloud backend, and we cannot read your chat history. See Section 4 for what is transiently processed when you send a message.

2.6 Analytics and diagnostics (pseudonymous)

To understand feature usage and fix crashes we collect:

Both are keyed to a one-way SHA-256 hash of your account ID — a pseudonym that lets us count unique users and follow a crash across sessions without exposing who you are. Your email, name, and IP address are actively stripped from crash reports before they are sent.

2.7 What we do not collect

Klense requests no access to your camera, photos, microphone, location, contacts, motion data, or Apple Health. The app contains no advertising SDKs, does not access the advertising identifier (IDFA), and does not track you across other companies' apps or websites. Notifications are generated locally on your device; we operate no push-notification server.

Like any online service, the servers listed in Section 5 technically observe your device's IP address when the app connects; we do not use IP addresses to identify or profile you.

3. Where your data lives

All reads happen from a local database on your device. Sections 2.1–2.4 sync to your private account in our cloud backend (Supabase, hosted in the United States — AWS US East, North Virginia) so your data restores if you reinstall or switch devices. Access is enforced per-account with row-level security: your data is readable and writable only by your authenticated account. Data stored only on your device and never synced: AI chat history, your AI data-sharing consent choice, and notification preferences.

4. The AI coach and Google Gemini

The AI coach is powered by Google Gemini and is part of Klense Premium; your subscription is verified before any request reaches Google (Section 2.4). Before your first message is sent, the app shows a disclosure and asks for your explicit permission; nothing is shared until you agree, and you can decline and still use the rest of the app.

When you send a message, the app transmits the following through our backend to Google's Gemini API to generate a reply:

Equally important, what is not sent to Google: your name, email address, account ID, device identifiers, subscription details (including the signed subscription record in Section 2.4), or completion timestamps. Google receives the content above with no identifier linking it to you as a person. Klense does not store your messages or the AI's replies on its servers — only the daily usage counters in Section 2.3. Google processes this data as our service provider to generate the response, subject to Google's Gemini API terms; Klense does not permit its use for advertising.

The AI coach is an automated assistant, not a human, and its guidance is educational — not medical advice. You can report any objectionable AI response by touch-and-holding the reply and choosing Report.

5. Service providers

We share personal information only with the service providers below, only so they can run the app for us, and never for their own advertising:

ProviderRoleData processed
SupabaseBackend: authentication, database, sync, serverless functionsEmail, account ID, and the synced data in Sections 2.1–2.4
Google (Gemini API)Generates AI coach repliesThe per-message content in Section 4, with no account identifiers; only after your explicit consent
ApplePayments, subscriptions, sign-inHandled under Apple's own terms; Apple does not give us your payment details
SuperwallHosts and configures the paywall; runs paywall experimentsYour subscription status and the outcome of each purchase or restore, keyed to an identifier Superwall generates for your device — we never send it your email, name, or account ID
MixpanelUsage analytics (US-hosted)Pseudonymous usage events (Section 2.6) keyed to a hashed account ID
SentryCrash and error reporting (US-hosted)Crash/error reports (Section 2.6) keyed to a hashed account ID; IP addresses suppressed

We do not sell personal information, do not share it for cross-context behavioral advertising, and do not disclose it to anyone else except: (a) at your direction, (b) to comply with law or valid legal process, (c) to protect the rights, safety, or security of Klense or its users, or (d) in a merger, acquisition, or sale of assets — in which case this policy continues to apply until you are notified otherwise.

6. How we use your information

We do not use your personal information to train AI models, and we do not permit our providers to do so on our behalf.

7. Data retention

8. Your rights and controls

Built into the app, no support ticket required:

Depending on where you live (e.g. the EEA/UK under GDPR, or California under the CCPA/CPRA), you may also have rights to access, correct, delete, port, or restrict processing of your personal information, to withdraw consent, to opt out of "sale"/"sharing" (we do neither), and to complain to your data-protection authority. To exercise any right, use the in-app tools above or email klensebusiness@gmail.com. We will not discriminate against you for exercising your rights.

9. Security

Data in transit is protected with TLS. Cloud data is protected with per-account row-level security so only your authenticated session can access your records. Sign-in sessions are stored in the iOS Keychain. The AI provider key is held server-side and never shipped in the app. No system is perfectly secure, but we design so that a breach of any one component exposes as little as possible.

10. International transfers

Our service providers process data in the United States. If you use Klense from outside the U.S., your information will be transferred to and processed in the U.S. under this policy and appropriate safeguards with our providers.

11. Children

Klense is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.

12. Changes to this policy

We will post any changes here and update the date at the top. For material changes we will notify you in the app before they take effect. Your continued use after notice means you accept the updated policy.

13. Contact

Cole Thapanawat, sole proprietor 169 Wishbone Bnd, State College, PA 16801 klensebusiness@gmail.com